US2024430274A1PendingUtilityA1

Ransomware detection and/or remediation as a service in file server systems

Assignee: NUTANIX INCPriority: Jun 26, 2023Filed: Oct 31, 2023Published: Dec 26, 2024
Est. expiryJun 26, 2043(~16.9 yrs left)· nominal 20-yr term from priority
H04L 63/1416
43
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Examples of analytics systems may include a cloud based no-touch auto-update mechanism that may have access to ransomware signatures. For example, the service may pull ransomware signatures from a centralized public datastore through APIs and update the ransomware signatures on file servers subscribed to the analytics system.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A system comprising:
 a repository of ransomware signatures, each of the ransomware signatures including a pattern of file events indicative of a ransomware attack;   an analytics system configured to periodically access a source of ransomware signatures and identify new or changed ransomware signatures and to provide changed or updated ransomware signatures to file servers subscribed to a ransomware signature update service.   
     
     
         2 . The system of  claim 1 , wherein the analytics system is configured to prevent adding a ransomware signature from the repository to a particular file server when the particular client has previously blocked the ransomware signature. 
     
     
         3 . The system of  claim 1 , wherein the analytics system is configured to allow additional ransomware signatures at a particular file server when the particular file server has added the ransomware signature. 
     
     
         4 . The system of  claim 1 , wherein the analytics system is configured to detect a new ransomware signature based on a ransomware attack on one of the file servers, the analytics system further configured to distribute the new ransomware signature to other ones of the file servers. 
     
     
         5 . The system of  claim 1 , wherein the analytics system comprises a listener service configured for periodic communication with the repository of ransomware signatures. 
     
     
         6 . The system of  claim 1 , wherein the pattern of file events indicative of the ransomware attacks include a rename event. 
     
     
         7 . The system of  claim 1  wherein at least one of the file servers includes a local ransomware signature repository, and wherein the changed or updated ransomware signatures are used to update the local ransomware signature repository. 
     
     
         8 . The system of  claim 7 , wherein the at least one of the file servers is configured to remediate a ransomware attack based on the local ransomware signature repository. 
     
     
         9 . A method comprising:
 periodically connecting to a ransomware signature repository to identify a new or changed ransomware signature, wherein the new or changed ransomware signature is based on a pattern of file events;   comparing the new or changed ransomware signature with ransomware signatures stored locally at a file server; and   updating the file server with the new or changed ransomware signature based on said comparing.   
     
     
         10 . The method of  claim 9 , wherein said periodically connecting comprises transmitting an API call to the ransomware signature repository. 
     
     
         11 . The method of  claim 9 , further comprising identifying a deleted ransomware signature based on the ransomware signature repository. 
     
     
         12 . The method of  claim 9 , wherein said updating the file server comprises updating a behavior of a file blocking policy of the file server. 
     
     
         13 . The method of  claim 9 , further comprising refraining from updating a second file server with the new or changed ransomware signature when the second file server had previously removed the new or changed ransomware signature. 
     
     
         14 . The method of  claim 9 , further comprising determining a particular sequence of events has occurred previously at a second file server; and
 refraining from updating the second file server with the new or changed ransomware signature when the new or changed ransomware signature includes the particular sequence of events.   
     
     
         15 . The method of  claim 9 , further comprising:
 identifying a second ransomware signature based on a ransomware attack occurring on the file server; and   updating the ransomware signature repository with the second ransomware signature.   
     
     
         16 . The method of  claim 9 , further comprising distributing the new or changed ransomware signature to multiple file servers in accordance with a prioritization rule. 
     
     
         17 . The method of  claim 16 , wherein the prioritization rule comprises a rule which prioritizes distribution of the new or changed ransomware signature to file servers associated with a same tenant from which the new or changed ransomware signature was discovered. 
     
     
         18 . The method of  claim 9 , further comprising identifying pre-existing infection on the file server based on the new or changed ransomware signature. 
     
     
         19 . The method of  claim 9 , further comprising identifying a malicious client based on the new or changed ransomware signature. 
     
     
         20 . At least one non-transitory computer readable media encoded with instructions which, when executed, cause a system to perform operations comprising:
 periodically connecting to a ransomware signature repository to identify a new or changed ransomware signature, wherein the new or changed ransomware signature is based on a pattern of file events;   comparing the new or changed ransomware signature with ransomware signatures stored locally at a file server; and   updating the file server with the new or changed ransomware signature based on said comparing.   
     
     
         21 . The non-transitory computer readable media of  claim 20 , wherein the operations further comprise refraining from updating a second file server with the new or changed ransomware signature when the second file server had previously removed the new or changed ransomware signature. 
     
     
         22 . The non-transitory computer readable media of  claim 20 , wherein the operations further comprise:
 identifying a second ransomware signature based on a ransomware attack occurring on the file server; and   updating the ransomware signature repository with the second ransomware signature.   
     
     
         23 . The non-transitory computer readable media of  claim 20 , wherein the operations further comprise distributing the new or changed ransomware signature to multiple file servers in accordance with a prioritization rule. 
     
     
         24 . The non-transitory computer readable media of  claim 23 , wherein the prioritization rule comprises a rule which prioritizes distribution of the new or changed ransomware signature to file servers associated with a same tenant from which the new or changed ransomware signature was discovered.

Join the waitlist — get patent alerts

Track US2024430274A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.